SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔'s Avatar

SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔

@techbytom

Privacy, motorcycle, and craft beer geek. Adversarial thinker. Blue team your blue team for better red teaming.

183
Followers
347
Following
200
Posts
16.08.2023
Joined
Posts Following

Latest posts by SecByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ @techbytom

Preview
The Government Just Made it Harder to See What Spy Tech it Buys On Wednesday, the government stopped supporting FPDS.gov, an indispensable resource for finding what ICE, the FBI, and every other agency is buying. Its replacement site completely sucks.

The U.S. government on Wednesday shut down a vital resource for keeping tabs on what powerful spying tools its agencies are buying, making it harder to reliably find out how agencies including ICE are spending taxpayers’ dollars. www.404media.co/the-governm...

28.02.2026 19:33 👍 182 🔁 96 💬 2 📌 2

Remember when we all used to talk about how invasive the “Great Firewall of China” was?

Pepperidge Farm remembers.

Now we buy cameras for our front doors so they can ID anyone on our street and report their location in real time. Photo IDs to use the internet. Etc etc. is this the future we want?

28.02.2026 19:28 👍 3 🔁 2 💬 0 📌 0

This implies it can’t be used on patrol. Interesting.

26.02.2026 14:08 👍 1 🔁 0 💬 0 📌 0
Preview
Analysis https://ghda111k.de/Hello Malicious activity - Interactive analysis ANY.RUN Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

Anyone want to burn down some criminal's infra? app.any.run/tasks/63ba90... Live right now

25.02.2026 04:06 👍 0 🔁 0 💬 0 📌 0

Note: this is illegal in Illinois?

24.02.2026 20:21 👍 0 🔁 0 💬 0 📌 0

New TTP added to my list today because I was working on implementing security controls. This falls into my favorite category: features with unintended consequences. Also it’s a lolbin. Not yet in LOLBAS.

24.02.2026 16:44 👍 0 🔁 0 💬 0 📌 0
Post image

And as long as you don't care about privacy at all, you should be good to go

23.02.2026 00:51 👍 0 🔁 0 💬 1 📌 0
Preview
ChatGPT ChatGPT helps you get answers, find inspiration, and be more productive.

TIL you can register with ChatGPT to offensive security use chatgpt.com/cyber

23.02.2026 00:50 👍 0 🔁 0 💬 1 📌 0
Preview
Google finds state-sponsored hackers use AI at 'all stages' of attack cycle New Google research reveals state-sponsored hackers are using Gemini across the entire cyberattack cycle to automate reconnaissance and tinker with malware.

Shock.
cyberscoop.com/state-hacker...

16.02.2026 21:27 👍 0 🔁 0 💬 0 📌 0

Take notes. THIS is how you articulate the difference between warm fuzzy marketing and propaganda for a commercial dystopia.

11.02.2026 05:15 👍 2 🔁 0 💬 0 📌 0

Good riddance @discord.com

10.02.2026 16:11 👍 0 🔁 0 💬 0 📌 0
Preview
Exclusive: Hacktivist scrapes over 500,000 stalkerware customers' payment records More than half-a-million people who bought access to phone surveillance and social media snooping apps had their email address and partial payment card numbers published online.

techcrunch.com/2026/02/09/h...

Hacktivism lives.

09.02.2026 20:30 👍 18 🔁 14 💬 0 📌 1
Automated Snow Removal for Truck Trailer Roofs | Scraper Systems™
Automated Snow Removal for Truck Trailer Roofs | Scraper Systems™ YouTube video by Scraper Systems by Rite-Hite

www.youtube.com/watch?v=Y5o3...

02.02.2026 17:56 👍 0 🔁 0 💬 0 📌 0
Privacy – Tessie Tessie is built for you—and only you.

LOOK AT THIS PRIVACY POLICY.
Look at it. You can read it because they don’t need a ton of legalese to make you stop reading all the ways they’ll sell your data.

They just don’t do that. None of it.

tessie.com/privacy

29.01.2026 02:28 👍 0 🔁 0 💬 0 📌 0

We want the soundtrack!

23.01.2026 20:25 👍 0 🔁 0 💬 0 📌 0
Preview
BSides312 - Chicago's Hacking Conference BSides312 is Chicago's biggest little non-profit hacking & information security conference.

Early bird tickets are still available! 🎉
Use code BS312-EB20 to get 20% off your #BSides312 ticket.

Grab yours now 👉 bsides312.org
While you’re there, consider volunteering and helping make the event awesome!
#BSides

16.01.2026 21:31 👍 2 🔁 1 💬 0 📌 0

cupholder.exe was one of my favorite memories when growing up.

18.01.2026 21:26 👍 2 🔁 0 💬 0 📌 0

To be clear. NetNTLMv1 support needs to go. But for the low security budgets, the companies that can’t navigate their way out from under this one, detection and effective response will be your saving grace (or it won’t be).

16.01.2026 03:34 👍 0 🔁 0 💬 0 📌 0
Preview
Releasing Rainbow Tables to Accelerate Protocol Deprecation | Google Cloud Blog Mandiant aims to lower the barrier for security professionals to demonstrate the insecurity of Net-NTLMv1.

If your SOC doesn’t already alert on NetNTLM with challenges of “1122334455667788” you should fix that NOW.

cloud.google.com/blog/topics/...

15.01.2026 16:35 👍 4 🔁 4 💬 1 📌 1
Preview
Combining NVIDIA DGX Spark + Apple Mac Studio for 4x Faster LLM Inference with EXO 1.0 Disaggregating Prefill and Decode: Faster First Tokens, Faster Streams

If you’re not watching EXO labs, and you have any good reason to run local LLMs stop now and read blog.exolabs.net/nvidia-dgx-s...

06.01.2026 05:45 👍 1 🔁 0 💬 0 📌 0
Preview
vmux Run anything in the cloud. Replace uv run with vmux run.

Fun way to host your payloads vmux.sdan.io

02.01.2026 01:27 👍 1 🔁 0 💬 0 📌 0

Did you know your taxes were being used to buy your flight records from commercial airlines so your movement could be tracked without a warrant?

01.01.2026 19:24 👍 0 🔁 0 💬 0 📌 0

This is fork&run to execute BOFs in a remote process, same API, and get output back over a pipe--demonstrated with Havoc.

Same arch could support explicit injection. Add-in an injector artifact + psexec, could remotely run a BOF without an agent and get output back too. bofexec? :)

31.12.2025 23:51 👍 6 🔁 1 💬 0 📌 0
Preview
You've been targeted by government spyware. Now what? | TechCrunch Tech companies are increasingly warning their customers that they have been targeted by governments with advanced government spyware, such as NSO's Pegasus or Paragon's Graphite. What happens after re...

NEW: Apple, Google, and WhatsApp now regularly notify their users if they suspect they have been targeted or hacked with government spyware, such as that made by NSO Group or Paragon.

We spoke to experts and wrote a guide on what to do, and where to go, if you receive one of those notifications.

29.12.2025 16:27 👍 30 🔁 25 💬 0 📌 1

This tool is an especially powerful and widely applicable one. Don’t get caught up in saying no, infosec.

27.12.2025 00:33 👍 1 🔁 0 💬 0 📌 0
Post image

ORLY?

20.12.2025 04:47 👍 0 🔁 0 💬 0 📌 0

This implies that getting a warrant for this was anything other than a rubber stamp in a web interface before now.

NARRATOR (V.O.) It wasn't.

19.12.2025 15:23 👍 0 🔁 0 💬 0 📌 0

30% of the code, and 100% of the design is now done by AI

19.12.2025 15:02 👍 0 🔁 0 💬 0 📌 0

0nrnicrosoft[.]com was registered last night

19.12.2025 14:57 👍 0 🔁 0 💬 0 📌 0

When 2040 me can’t give someone a dirty look without it being captured, catalogued, and sold to the surveillance state - this is one of the ways we got there.

19.12.2025 14:18 👍 0 🔁 0 💬 0 📌 0